CVE-2015-6908: Input Validation
The bergetnext function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6908?
CVE-2015-6908 has a severity rating that suggests it can lead to a denial of service due to application crashes.
How do I fix CVE-2015-6908?
To address CVE-2015-6908, upgrade to OpenLDAP version 2.4.43 or later, which resolves the vulnerability.
What systems are affected by CVE-2015-6908?
CVE-2015-6908 affects OpenLDAP 2.4.42 and earlier as well as macOS Yosemite 10.11.1.
What type of attack does CVE-2015-6908 enable?
CVE-2015-6908 enables remote attackers to perform denial of service attacks through crafted BER data.
Is CVE-2015-6908 exploitable over the network?
Yes, CVE-2015-6908 is exploitable remotely, allowing attackers to cause a denial of service on affected systems.